A method, device and equipment for automatically collecting evidence of alarm logs and exporting reports
Through the automated processing of obtaining alarm logs and generating reports, the problem of massive alarm information processing is solved, automatic evidence collection and report export are realized, the pressure on security operation personnel is alleviated, and processing efficiency is improved.
Patent Information
- Application Number
- CN202310080387.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-13
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-01-13
AI Technical Summary
In the prior art, massive alarm information leads to high disposal costs for security operation personnel, numerous noise-level alarms, making it difficult to efficiently and automatically process alarm logs and export reports.
By obtaining the alarm log, determining the target evidence collection address, conducting evidence collection investigation operations, using the preset operation information set and the inclusion relationship of the evidence collection investigation operation information, updating the operation information set, and generating a report based on the evidence collection result data.
It realizes automatic evidence processing of alarm logs and automatic export of reports, reducing the pressure on security operation personnel, improving processing efficiency, and having good practicality and compatibility.
Smart Images

Figure CN116094813B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network security technology, and in particular to a method, device and equipment for automatically collecting evidence from alarm logs and exporting reports. Background Art
[0002] With the rapid development of the Internet, its scale is constantly expanding and its applications are becoming more extensive. The key business activities of many departments and enterprises are increasingly dependent on the Internet, and the incidence of various network attacks and information security incidents is constantly rising. Quickly and accurately handling security incidents and reducing security incidents have become important goals of modern security incident management.
[0003] How to determine when the alarm was initiated and who initiated the attack based on the alarm log is an essential part of handling network security incidents. However, in the current security system construction process, enterprises will enhance threat perception capabilities by introducing more detection equipment, but the alarm handling costs brought by this are also huge, and the massive "noise" level alarms often make security operators very annoyed.
[0004] Therefore, people are in urgent need of a method that can automatically process alarm logs, automatically collect evidence based on alarm logs, and automatically export reports to alleviate the pressure on security operations personnel. Summary of the invention
[0005] In view of this, it is necessary to provide a method, device and equipment for automatic evidence collection and report export of alarm logs, so as to realize automatic evidence collection based on alarm logs and automatic report export, so as to relieve the pressure of security operators.
[0006] In order to achieve the above technical objectives, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a method for automatically collecting evidence from alarm logs and exporting reports, comprising:
[0008] Obtaining an alarm log, and obtaining a target forensic address based on the alarm log;
[0009] According to the page of the target evidence collection address, target evidence collection investigation operation information is obtained;
[0010] According to the target forensic investigation operation information, a target forensic investigation operation is performed based on a preset operation information set to obtain forensic result data, and according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information, the preset operation information set is updated;
[0011] According to the forensic results data, based on the preset report template, create and export the target report.
[0012] Further, performing a forensic investigation operation based on the preset operation information set according to the target forensic investigation operation information to obtain forensic result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information, includes:
[0013] Determine the type of the target forensic investigation operation information;
[0014] If the type of the target forensic investigation operation information is the no-operation type, capture a picture of the page at the target forensic address to obtain a target forensic screenshot;
[0015] If the type of the target forensic investigation operation information is the operation type, perform a target forensic investigation operation based on the preset operation information set to obtain forensic result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information;
[0016] Wherein, the forensic result data includes the target forensic screenshot.
[0017] Further, the preset operation information set includes multiple preset operation items, and each preset operation item corresponds to a type of forensic investigation operation information; performing a target forensic investigation operation based on the preset operation information set to obtain forensic result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information, includes:
[0018] Determine whether the preset operation information set includes a preset operation item corresponding to the target forensic operation information;
[0019] If so, perform a target forensic investigation operation according to the preset operation item corresponding to the target forensic operation information in the preset operation information set, and obtain the forensic result data;
[0020] If not, after manually performing a forensic investigation operation, save the forensic investigation operation information performed manually, and create a corresponding preset operation item in the preset operation information set.
[0021] Further, the target forensic operation information includes an alarm visual snapshot, and the preset operation item corresponding to the alarm visual snapshot includes:
[0022] Retrieve and locate the target position in the page at the target forensic address;
[0023] Capture a picture of the target position in the page at the target forensic address.
[0024] Further, the target report includes a general report and a customized report; establishing and exporting a target report based on the forensic result data and a preset report template includes:
[0025] Determine the type of the target report;
[0026] If the type of the target report is a general report, establish and export a target general report according to the forensic result data;
[0027] If the type of the target report is a customized report, establish and export a target customized report based on the forensic result data and a preset report template.
[0028] Further, the preset report template is manually established according to a sample report. The preset report template includes a content document and a rendering mapping file. The content document includes multiple replacement variable fields, and the rendering mapping file includes rendering elements for each of the replacement variable fields; establishing and exporting a target customized report based on the forensic result data and a preset report template includes:
[0029] Render the replacement variable fields according to the rendering mapping file, and combine with the content document to obtain an expected page rendering effect;
[0030] Establish a correspondence between the replacement variable fields and the forensic result data according to the expected page rendering effect;
[0031] Replace the replacement variable fields in the content document according to the correspondence between the variable replacement fields and the forensic result data, and obtain and export the target customized report.
[0032] Further, it also includes:
[0033] Judge whether login is required according to the page of the target forensic address;
[0034] If so, log in to the page of the target forensic address and cache the login token for a preset time.
[0035] In a second aspect, the present invention also provides a device for automatically forensically obtaining and exporting a report of alarm logs, including:
[0036] An address acquisition module, configured to acquire alarm logs and obtain a target forensic address according to the alarm logs;
[0037] An operation analysis module, configured to obtain target forensic investigation operation information according to the page of the target forensic address;
[0038] The evidence collection and investigation module is used to perform a target evidence collection and investigation operation based on the preset operation information set according to the target evidence collection and investigation operation information, obtain evidence collection result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection and investigation operation information;
[0039] The report generation module is used to establish and export a target report based on the preset report template according to the evidence collection result data.
[0040] Thirdly, the present invention also provides an electronic device, including a memory and a processor, wherein,
[0041] The memory is used to store programs;
[0042] The processor is coupled to the memory and is used to execute the programs stored in the memory to implement the steps in the method for automatically collecting evidence from alarm logs and exporting reports in any of the above implementation manners.
[0043] Fourthly, the present invention also provides a computer-readable storage medium for storing computer-readable programs or instructions. When the programs or instructions are executed by a processor, the steps in the method for automatically collecting evidence from alarm logs and exporting reports in any of the above implementation manners can be implemented.
[0044] A method, device and equipment for automatically collecting evidence from alarm logs and exporting reports provided by the present invention first obtains alarm logs, obtains a target evidence collection address according to the alarm logs, then obtains target evidence collection and investigation operation information according to the page of the target evidence collection address, then performs a target evidence collection and investigation operation based on the preset operation information set according to the target evidence collection and investigation operation information, obtains evidence collection result data, and updates the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection and investigation operation information, and finally establishes and exports a target report based on the preset report template according to the evidence collection result data. Compared with the prior art, the present invention realizes the automatic evidence collection processing of alarm logs through the preset operation information set, and realizes the method of automatically exporting reports. At the same time, the preset operation information set can also be automatically updated according to specific situations to dynamically improve its own compatibility, so that the present invention can perfectly handle a large number of alarm logs, greatly alleviating the pressure on security operation personnel and having good practicability. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 It is a flowchart of a method of an embodiment of the method for automatically collecting evidence from alarm logs and exporting reports provided by the present invention;
[0046] Figure 2 is Figure 1 a flowchart of a method of an embodiment of step S103 in
[0047] Figure 3 is Figure 2 a flowchart of a method for an embodiment of step S203;
[0048] Figure 4 is Figure 1 a flowchart of a method for an embodiment of step S104;
[0049] Figure 5 is a schematic structural diagram of an embodiment of a device for automatically collecting evidence of alarm logs and exporting reports provided by the present invention;
[0050] Figure 6 is a schematic structural diagram of an embodiment of an electronic device provided by the present invention. Detailed Embodiments
[0051] The following describes the preferred embodiments of the present invention in detail with reference to the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.
[0052] In the description of this application, "a plurality of" means two or more, unless otherwise specifically defined.
[0053] Referring to "embodiments" herein means that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0054] Before elaborating on the specific embodiments, some specific terms in this article are first explained:
[0055] soar: Security Orchestration, Automation and Response, which is mainly applied to orchestrating soar scripts in practice. Orchestrating soar scripts means flexibly organizing and dragging connections of various applications according to scenarios such as daily security operations and guarantees. With rich application access capabilities, various scenario capabilities can be flexibly organized for orchestration, and visualization technology is used to achieve visual processes for complex operations.
[0056] Intelligent Security and Collaborative Command Center: An intelligent automation software platform implemented based on soar.
[0057] Application: It can also be called a plug-in or a scaffolding program. Similar to an app, the applications in this article can refer to various installable and runnable apps supported on the "Intelligent Security and Collaborative Command Center" platform. The steps in this embodiment are mainly carried out in the application.
[0058] Action: It can be some functions executable within an application, or a certain step within that function.
[0059] Through an application including a preset operation information set, the present invention automatically executes actions such as investigation and evidence collection through the preset operation information set, and automatically generates and exports a report based on the evidence collection result data, realizing the automated processing of alarm information and the exported report.
[0060] The present invention provides a method, device, equipment, and storage medium for automatically collecting evidence from alarm logs and exporting reports, which will be described separately below.
[0061] Combined with Figure 1 As shown, a specific embodiment of the present invention discloses a method for automatically collecting evidence from alarm logs and exporting reports, including:
[0062] S101. Obtain the alarm log and obtain the target evidence collection address according to the alarm log;
[0063] S102. Obtain the target evidence collection investigation operation information according to the page of the target evidence collection address;
[0064] S103. Based on the target evidence collection investigation operation information, perform a target evidence collection investigation operation based on the preset operation information set to obtain evidence collection result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information;
[0065] S104. Based on the evidence collection result data, establish and export a target report based on a preset report template.
[0066] A method, device, and equipment for automatically collecting evidence from alarm logs and exporting reports provided by the present invention first obtain alarm logs, obtain a target evidence collection address based on the alarm logs, then obtain target evidence collection investigation operation information based on the page of the target evidence collection address, and then based on the target evidence collection investigation operation information, perform a target evidence collection investigation operation based on a preset operation information set to obtain evidence collection result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information. Finally, based on the evidence collection result data, a target report is established and exported based on a preset report template. Compared with the prior art, the present invention realizes the automatic evidence collection processing of alarm logs through a preset operation information set, and also realizes the method of automatically exporting reports. At the same time, the preset operation information set can also be automatically updated according to specific situations to dynamically improve its own compatibility, enabling the present invention to perfectly handle a large number of alarm logs, greatly alleviating the pressure on security operation personnel, and having good practicability.
[0067] In a preferred embodiment, in step S101, alarm logs can be obtained from a third-party platform such as situational awareness through methods such as Kafka, Syslog, and API, and a target evidence collection address can be obtained from the alarm logs.
[0068] In a preferred embodiment, the target evidence collection investigation operation information in step S102 refers to the operations that need to be performed on the page during the evidence collection process and the information required for these operations, such as clicking, inputting data, as well as the positioning of elements to be operated on the page, input and output content, etc. The target evidence collection investigation operation information can be obtained from the source code of the page of the target evidence collection address.
[0069] Further, as shown in Figure 2 In a preferred embodiment, steps S103, based on the target evidence collection investigation operation information, perform a target evidence collection investigation operation based on a preset operation information set to obtain evidence collection result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information, specifically include:
[0070] S201. Determine the type of the target evidence collection investigation operation information;
[0071] S202. If the type of the target evidence collection investigation operation information is a no-operation type, intercept a picture of the page of the target evidence collection address to obtain a target evidence collection screenshot;
[0072] S203. If the type of the target forensic investigation operation information is an operation type, perform a target forensic investigation operation based on the preset operation information set to obtain forensic result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information;
[0073] Among them, the forensic result data includes the target forensic screenshot. The non-operation type means the situation where no operation needs to be performed on the page, and the operation type means the situation where an operation is required.
[0074] Specifically, as shown in Figure 3 In a preferred embodiment, the preset operation information set in the above process includes multiple preset operation items, and each preset operation item corresponds to a forensic investigation operation information. Steps S203 in the above process, performing a target forensic investigation operation based on the preset operation information set to obtain forensic result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensic investigation operation information, include:
[0075] S301. Determine whether the preset operation information set includes a preset operation item corresponding to the target forensic operation information;
[0076] S302. If so, perform a target forensic investigation operation according to the preset operation item corresponding to the target forensic operation information in the preset operation information set, and obtain the forensic result data;
[0077] S303. If not, after manually performing a forensic investigation operation, save the forensic investigation operation information performed manually, and create a corresponding preset operation item in the preset operation information set.
[0078] Further, in a preferred embodiment, the target forensic operation information in the above process includes an alarm visual snapshot, and the preset operation items corresponding to the alarm visual snapshot include:
[0079] Retrieve and locate the target position in the page of the target forensic address;
[0080] Capture a picture of the target position in the page of the target forensic address.
[0081] The present invention also provides a more detailed embodiment to more clearly illustrate the above steps S201 - S203:
[0082] 1. Determine whether the address to be forensically investigated (i.e., the target forensic address) requires a page click to input data operation.
[0083] If no page operation is required (i.e., the target forensic investigation operation information is of the no-operation type), the forensic page is opened based on the webdriver technology, and the program automatically takes a screenshot (obtaining the target forensic screenshot) and saves it to the disk, closes the forensic page, and exits the program;
[0084] If an operation is required (i.e., the target forensic investigation operation information is of the operation type), select the corresponding action in the "Investigative Forensics" application. The application will fill in the positioning information for the relevant operation based on the corresponding preset operation information set (the preset operation information set corresponds to the application or the action in the application and is the data source for its execution code), and thus the screenshot forensics with operations can be completed (i.e., the target forensic investigation operation is carried out, and the forensics result data is obtained), and the picture is saved on the disk.
[0085] 2. The target forensic operation and its corresponding target forensic operation information can be divided into different types. The alarm visual snapshot is one of them. If the address to be forensically investigated that requires an operation is within the platform, select the "Alarm Visual Snapshot" action in the "Investigative Forensics" application, and this application will automatically retrieve the positioning log in the preset operation information set and automatically take screenshots for forensics;
[0086] If the address to be forensically investigated that requires an operation is not within the platform, an action can be added in the "Investigative Forensics" application, or a new application can be added (i.e., update the preset operation entries in the preset operation information set), so as to achieve the subsequent function expansion and seamless docking of the application to expand compatibility. For example, in the intelligent security and collaborative command center software platform, directional forensics operations for many preset common websites are provided for the network security industry.
[0087] It should be noted that because the operations required for different pages are different, and the element positioning on the page is also different. Some input boxes are in the middle of the page, some are in the upper left corner, some require entering an IP, and some require entering a date, and the requirements are all different. The above-mentioned alarm visual snapshot is only one of the operations, and in practice, it can also be other operations, such as entering an IP, entering a date, etc. Similarly, the forensics result data obtained from different operations is also different.
[0088] 3. Upload the pictures saved on the disk to the file server for encrypted storage.
[0089] Furthermore, as shown in Figure 4 In a preferred embodiment, the target report in the above process includes a general report and a customized report. Step S104, based on the forensics result data, establish a target report and export it based on a preset report template, specifically including:
[0090] S401. Determine the type of the target report;
[0091] S402. If the type of the target report is a general report, establish and export a target general report according to the evidence collection result data;
[0092] S403. If the type of the target report is a customized report, establish and export a target customized report based on a preset report template according to the evidence collection result data.
[0093] Specifically, in a preferred embodiment, the preset report template in the above process is manually established according to a sample report. The preset report template includes a content document and a rendering mapping file. The content document includes multiple replacement variable fields, and the rendering mapping file includes rendering elements for each of the replacement variable fields. Step S403, establishing and exporting a target customized report based on the preset report template according to the evidence collection result data specifically includes:
[0094] Render the replacement variable fields according to the rendering mapping file, and combine with the content document to obtain an expected page rendering effect;
[0095] Establish a correspondence between the replacement variable fields and the evidence collection result data according to the expected page rendering effect;
[0096] Replace the replacement variable fields in the content document according to the correspondence between the variable replacement fields and the evidence collection result data to obtain and export the target customized report.
[0097] The present invention also provides a more detailed embodiment to more clearly illustrate the above steps S401 - S403:
[0098] General report generation: A set of standard programs are provided in the application, which can be configured and data - entered by the user, select the file type as word or PDF, and generate dynamically. The specific operation process is as follows:
[0099] 1. Select the "General Report" application in the application list, select the "Generate Report" action, and enter the configuration page.
[0100] 2. Enter the report theme.
[0101] 3. According to business needs, configure the first - level title name, the content of the first - level title, the second - level title name, and the second - level title content. It can be configured multiple times as needed, support user input, and at the same time support obtaining from the response data (i.e., the evidence collection result data) of the upstream - dependent application.
[0102] 4. Illustrations can be configured in two ways: uploaded from the local or selected from the response data of the upstream dependent application. Multiple pictures are supported, and mainstream picture formats (such as png, jpg, jpeg, etc.) are supported. In the general report of this embodiment, the illustrations are uniformly placed at the end of the report.
[0103] 5. If the upstream dependent application is for investigation and evidence collection, the pictures generated by the evidence collection can be obtained from the response and placed as illustrations at the specified position in the report.
[0104] 6. Select the report format: word or PDF.
[0105] 7. The program obtains the values entered by the user on the page or the values from the response of the upstream dependent application, as well as the picture information, and starts to assemble the report structure in sequence, assemble the data, write to the file, and generate the final report.
[0106] Customized report generation: Customization based on detailed business scenarios. The user provides a sample file, and the engineer intervenes to organize the sample file, reset the content that needs to be dynamically replaced by the program in the sample as variables (i.e., replace the variable fields), and form a word template file (i.e., the content document). At the same time, based on the content document, arrange the input mapping values for the dynamic rendering page to form a rendering mapping file with rendering elements. Select the file type as word or PDF for customized generation.
[0107] The specific operations are as follows:
[0108] 1. The requester provides a report as a sample reference.
[0109] 2. The engineer intervenes to organize the sample file into a word template, and change the places that require logical calculations, business statistics, dynamic changes of pictures and text in the sample file to the following format.
[0110]
[0111] 3. At the same time, organize a rendering mapping file, that is: map the English name, Chinese name, and corresponding rendering elements of each variable one by one. The format is as follows:
[0112]
[0113]
[0114] 4. In the "Customized Report" application, add an action. The action name can be defined by the report name, such as the Daily Security Report, and place the above-generated content document and rendering mapping file in the file directory of this action.
[0115] 5. In the script arrangement, select "Daily Safety Report", and the rendering mapping file can be dynamically loaded and rendered. According to the Chinese names and page rendering element information in the file, the content that needs to be dynamically replaced by the program in the report is rendered, and the expected page effects of each variable field (i.e., the expected page rendering effects) are rendered, so that users can intuitively input values or select values from the response data of the upstream dependent application, or through program comparison operations, form a one-to-one mapping between variable fields and values. It should be noted that the above-mentioned response data of the upstream dependent application can be the forensics result data described in this embodiment, or data in other applications.
[0116] 6. On the rendered page, variable values can be manually input, or values can be selected from the response data of the upstream dependent application. When encountering pictures, pictures can also be selected from the local disk. Then, the above data or pictures are used to replace the replacement variable fields in the content document.
[0117] 7. Select the report format: word or PDF.
[0118] 8. Parse and obtain the values input by the user on the page or the values responded from the upstream dependent application, load the word template file, and fill the data into the positions of the variables in the template according to the mapping file and the parsed obtained values to generate the final report.
[0119] In the above embodiment, automatic operation is achieved during the forensics and report generation process. The operator only needs to select the type of target document and the forensics action to be performed to obtain the result.
[0120] In a preferred embodiment, the method for automatically forensics and exporting reports of the above warning logs further includes the steps of:
[0121] Judge whether login is required according to the page of the target forensics address;
[0122] If so, log in to the page of the target forensics address and cache the login token for a preset time.
[0123] In this embodiment, the token is cached for 30 minutes to avoid repeated logins within 30 minutes. The above steps can be executed before step S102.
[0124] The scenarios to which the present invention can be applied are as follows:
[0125] 1. Automatic generation of daily weekly reports and monthly reports
[0126] In daily operation and maintenance work, it is often necessary to report weekly and monthly reports on various types of data. Since manual data collection, summarization, and calculation are very inefficient and time-consuming, program automation is required to improve efficiency. The input of this scenario is "relevant alarm log data of the big data system", and the output is "customized daily, weekly, and monthly reports". In this method, various types of data can be obtained by smart automation docking with the big data system based on soar. After passing through a customized template, various required reports are automatically formed. Based on the idea of the present invention, the brief process to achieve the above goals is as follows:
[0127] (1) Docking with the big data system based on soar to receive relevant business data.
[0128] (2) Count all attack IPs today, count the total number of attacks yesterday, and calculate the percentage increase in the number of attacks compared to yesterday.
[0129] (3) Obtain all attack IPs, query the location of the attack IPs, and summarize the number of overseas attacks, the main countries from which they come, the number of domestic attacks, and the main provinces from which they come.
[0130] (4) Collect the above statistical data, customize the report template, and automatically generate a report.
[0131] 2. Summary of IP address traceability analysis
[0132] In daily operation and maintenance work, there are often a large number of threatening IPs, especially during the network security protection period. It is necessary to conduct screening and judgment, remove invalid IP information, trace the identified threatening IPs, and form a report for submission. The current manual work method is very inefficient, requiring manual screening and tracing, which takes a long time, especially during the network security protection period, and cannot meet the submission time limit requirements. The input of this scenario is the alarm log including a large number of threatening IP addresses, and the output is "a set of effective threatening IP addresses and portraits". In this method, detection and filtering can be automatically performed on threat intelligence and other systems or devices, and threat IP portraits can be formed through relevant security systems, and the effective threatening IPs can be traced. Based on the idea of the present invention, the brief process to achieve the above goals is as follows:
[0133] (1) Conduct IP traceability forensics, using the automatic screenshot forensics function of this method. The specific operations are as follows:
[0134] a. Simulate a browser to access the relevant threat intelligence center platform (if login is required to access here, log in first).
[0135] b. Enter the IP in the specified search box, click the search button, and enter the intelligence query result page.
[0136] c. Obtain the WHOIS registration information of the IP (registrant, email, contact phone number, address location), and perform IP reverse lookup (domain name information).
[0137] d. Take screenshots of these information pages and save them to the disk.
[0138] (2) Take screenshots of the above traceability results, and use the automatic report generation function of this method to generate a word report for reporting.
[0139] To better implement the method for automatically collecting alarm logs and exporting reports in the embodiments of the present invention, based on the method for automatically collecting alarm logs and exporting reports, correspondingly, please refer to Figure 5 , Figure 5 which is a schematic structural diagram of an embodiment of the device / system for automatically collecting alarm logs and exporting reports provided by the present invention. An apparatus 500 for automatically collecting alarm logs and exporting reports provided by an embodiment of the present invention includes:
[0140] An address acquisition module 510, configured to acquire alarm logs and obtain a target forensics address according to the alarm logs;
[0141] An operation analysis module 520, configured to obtain target forensics investigation operation information according to the page of the target forensics address;
[0142] A forensics investigation module 530, configured to perform a target forensics investigation operation based on a preset operation information set according to the target forensics investigation operation information, obtain forensics result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensics investigation operation information;
[0143] A report generation module 540, configured to establish and export a target report based on a preset report template according to the forensics result data.
[0144] It should be noted here that: the corresponding device 500 provided in the above embodiment can implement the technical solutions described in the above method embodiments. The specific implementation principles of the above modules or units can be referred to the corresponding content in the above method embodiments, and will not be elaborated here.
[0145] Please refer to Figure 6 , Figure 6The following is a schematic structural diagram of the electronic device provided by the embodiment of the present invention. Based on the above method for automatically collecting evidence and exporting reports from alarm logs, the present invention also correspondingly provides a device 600 for automatically collecting evidence and exporting reports from alarm logs, that is, the above-mentioned electronic device. The device 600 for automatically collecting evidence and exporting reports from alarm logs can be a computing device such as a mobile terminal, a desktop computer, a notebook, a palm computer, and a server. The device 600 for automatically collecting evidence and exporting reports from alarm logs includes a processor 610, a memory 620, and a display 630. Figure 6 Only some components of the device for automatically collecting evidence and exporting reports from alarm logs are shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented.
[0146] In some embodiments, the memory 620 may be an internal storage unit of the device 600 for automatically collecting evidence and exporting reports from alarm logs, such as the hard disk or memory of the device 600 for automatically collecting evidence and exporting reports from alarm logs. In other embodiments, the memory 620 may also be an external storage device of the device 600 for automatically collecting evidence and exporting reports from alarm logs, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the device 600 for automatically collecting evidence and exporting reports from alarm logs. Further, the memory 620 may also include both the internal storage unit and the external storage device of the device 600 for automatically collecting evidence and exporting reports from alarm logs. The memory 620 is used to store the application software installed on the device 600 for automatically collecting evidence and exporting reports from alarm logs and various types of data, such as the program code installed on the device 600 for automatically collecting evidence and exporting reports from alarm logs. The memory 620 may also be used to temporarily store the data that has been output or will be output. In one embodiment, a program 640 for automatically collecting evidence and exporting reports from alarm logs is stored on the memory 620, and the program 640 for automatically collecting evidence and exporting reports from alarm logs can be executed by the processor 610, thereby implementing the method for automatically collecting evidence and exporting reports from alarm logs in various embodiments of the present application.
[0147] In some embodiments, the processor 610 may be a central processing unit (CPU), a microprocessor, or other data processing chips, and is used to run the program code stored in the memory 620 or process data, such as executing the method for automatically collecting evidence and exporting reports from alarm logs.
[0148] The display 630 can be an LED display, a liquid crystal display, a touch liquid crystal display, an OLED (Organic Light-Emitting Diode) toucher, etc. in some embodiments. The display 630 is used to display the information of the device 600 that automatically obtains evidence from alarm logs and exports reports, and is also used to display a visual user interface. The components 610-630 of the device 600 that automatically obtains evidence from alarm logs and exports reports communicate with each other through a system bus.
[0149] In one embodiment, when the processor 610 executes the program 640 for automatically obtaining evidence from alarm logs and exporting reports in the memory 620, the steps in the method for automatically obtaining evidence from alarm logs and exporting reports as described above are implemented.
[0150] This embodiment also provides a computer-readable storage medium, on which a program for automatically obtaining evidence from alarm logs and exporting reports is stored. When the program for automatically obtaining evidence from alarm logs and exporting reports is executed by a processor, the steps in the above embodiment can be implemented.
[0151] A method, device, and equipment for automatically obtaining evidence from alarm logs and exporting reports provided by the present invention first obtain alarm logs, obtain a target evidence collection address according to the alarm logs, then obtain target evidence collection investigation operation information according to the page of the target evidence collection address, then perform a target evidence collection investigation operation based on a preset operation information set according to the target evidence collection investigation operation information, obtain evidence collection result data, update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information, and finally establish and export a target report based on a preset report template according to the evidence collection result data. Compared with the prior art, the present invention realizes the automatic evidence collection processing of alarm logs through a preset operation information set, and also realizes the method of automatically exporting reports. At the same time, the preset operation information set can also be automatically updated according to specific situations to dynamically improve its own compatibility, so that the present invention can perfectly handle a large number of alarm logs, greatly relieve the pressure on security operation personnel, and has good practicability.
[0152] As described above, the above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.
Claims
1. A method for automatically collecting evidence of alarm logs and exporting reports, characterized in that, including: Obtain an alarm log and obtain a target forensics address according to the alarm log; Obtain target forensics investigation operation information based on the page of the target forensics address; Based on the target forensics investigation operation information, perform a target forensics investigation operation based on a preset operation information set to obtain forensics result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensics investigation operation information; Based on the forensics result data, establish and export a target report based on a preset report template; The performing a forensics investigation operation based on the target forensics investigation operation information, based on a preset operation information set to obtain forensics result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensics investigation operation information includes: Judge the type of the target forensics investigation operation information; If the type of the target forensics investigation operation information is a no-operation type, capture a picture of the page of the target forensics address to obtain a target forensics screenshot; If the type of the target forensics investigation operation information is an operation type, perform a target forensics investigation operation based on the preset operation information set to obtain forensics result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensics investigation operation information; Wherein, the forensics result data includes the target forensics screenshot; The preset operation information set includes a plurality of preset operation items, and each preset operation item corresponds to a forensics investigation operation information; the performing a target forensics investigation operation based on the preset operation information set to obtain forensics result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target forensics investigation operation information includes: Judge whether the preset operation information set includes a preset operation item corresponding to the target forensics operation information; If so, perform a target forensics investigation operation according to the preset operation item corresponding to the target forensics operation information in the preset operation information set, and obtain the forensics result data; If not, after manually performing a forensics investigation operation, save the forensics investigation operation information performed manually, and create a corresponding preset operation item in the preset operation information set.
2. The method for automatically forensically analyzing and exporting a report of the alarm log according to claim 1, wherein, The target forensics operation information includes an alarm visual snapshot, and the preset operation item corresponding to the alarm visual snapshot includes: Retrieve and locate a target position in the page of the target forensics address; Capture a picture of the target position in the page of the target forensics address.
3. The method for automatically forensically analyzing and exporting a report of an alarm log according to claim 1, wherein The target report includes a general report and a customized report; the establishing and exporting a target report based on a preset report template according to the forensics result data includes: Judge the type of the target report; If the type of the target report is a general report, establish and export a target general report according to the forensics result data; If the type of the target report is a customized report, establish and export a target customized report based on a preset report template according to the forensics result data.
4. The method for automatically collecting evidence from alarm logs and exporting reports according to claim 3, wherein The preset report template is manually established according to a sample report. The preset report template includes a content document and a rendering mapping file. The content document includes multiple replacement variable fields, and the rendering mapping file includes rendering elements for each of the replacement variable fields; Based on the evidence collection result data and the preset report template, establishing and exporting a target customized report includes: Rendering the replacement variable fields according to the rendering mapping file, and combining with the content document to obtain an expected page rendering effect; Establishing a correspondence between the replacement variable fields and the evidence collection result data according to the expected page rendering effect; Replacing the replacement variable fields in the content document according to the correspondence between the variable replacement fields and the evidence collection result data, to obtain the target customized report and export it.
5. The method for automatically collecting evidence from alarm logs and exporting reports according to claim 1, characterized in that It further includes: Judging whether login is required according to the page of the target evidence collection address; If so, logging in to the page of the target evidence collection address and caching the login token for a preset time.
6. An apparatus for automatically collecting evidence of alarm logs and exporting reports, characterized in that, It includes: An address acquisition module, configured to acquire an alarm log and obtain a target evidence collection address according to the alarm log; An operation analysis module, configured to obtain target evidence collection investigation operation information according to the page of the target evidence collection address; An evidence collection investigation module, configured to perform a target evidence collection investigation operation based on the preset operation information set according to the target evidence collection investigation operation information, obtain evidence collection result data, and update the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information; A report generation module, configured to establish and export a target report based on the evidence collection result data and the preset report template; Performing an evidence collection investigation operation based on the preset operation information set according to the target evidence collection investigation operation information, obtaining evidence collection result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information, includes: Judging the type of the target evidence collection investigation operation information; If the type of the target evidence collection investigation operation information is a no-operation type, intercepting a picture of the page of the target evidence collection address to obtain a target evidence collection screenshot; If the type of the target evidence collection investigation operation information is an operation type, performing a target evidence collection investigation operation based on the preset operation information set, obtaining evidence collection result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information; Wherein, the evidence collection result data includes the target evidence collection screenshot; The preset operation information set includes multiple preset operation items, and each preset operation item corresponds to a type of evidence collection investigation operation information; performing a target evidence collection investigation operation based on the preset operation information set, obtaining evidence collection result data, and updating the preset operation information set according to the inclusion relationship between the preset operation information set and the target evidence collection investigation operation information, includes: Judging whether a preset operation item corresponding to the target evidence collection operation information is included in the preset operation information set; If so, perform a target forensic investigation operation according to the preset operation entry corresponding to the target forensic operation information in the preset operation information set, and obtain the forensic result data; If not, after manually performing a forensic investigation operation, save the forensic investigation operation information performed manually, and create a corresponding preset operation entry in the preset operation information set.
7. An electronic device, characterized in that, It includes a memory and a processor, wherein, the memory is used for storing programs; the processor is coupled to the memory and is used for executing the programs stored in the memory to implement the steps in the method for automatically forensically collecting alarm logs and exporting reports according to any one of claims 1 to 5 above.
8. A computer-readable storage medium, characterized in that, It is used for storing computer-readable programs or instructions, and when the programs or instructions are executed by a processor, the steps in the method for automatically forensically collecting alarm logs and exporting reports according to any one of claims 1 to 5 above can be implemented.
Citation Information
Patent Citations
Network data processing method, device and system
CN112615857A
Method and device for processing alarm log and storage medium
CN114816895A